Skip to content

Prowler

v5.30.3 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

βœ“ No known CVEs patched
Read the diff β†’ Tool health β†’ What is this tool? β†’
This release patches 1 known CVE

Topics

aws azure cis-benchmark cloud cloudsecurity compliance
+12 more
cspm security forensics gcp gdpr hardening iam multi-cloud python security-audit security-hardening security-tools

Affected surfaces

auth

Summary

AI summary

Updates πŸ” Security, 🐞 Fixed, and API across a mixed release.

Full changelog

API

πŸ” Security

SDK

🐞 Fixed

  • CLI compliance summary tables no longer undercount findings mapped to multiple sections nor double-count a single finding mapped to several requirements within the same group/split, and the Provider column no longer leaks a value from another framework (#11567)

Security Fixes

  • GHSA-h8m9-jgf8-vwvp – SAML logins enforce email domain match and tenant membership, fixing cross‑tenant account takeover

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Prowler

Get notified when new releases ship.

Sign up free

About Prowler

Tool based on AWS-CLI commands for Amazon Web Services account security assessment and hardening.

All releases β†’

Related context

Earlier breaking changes

  • v5.34.0 Renames UI integration enable flags to past tense (e.g., UI_SENTRY_ENABLE β†’ UI_SENTRY_ENABLED).

Beta — feedback welcome: [email protected]